Skip to content

Photocopying a Guest's ID in Spain: Why Your Rental Can't

Updated Clara BajoClara Bajo
Cobalt-blue azulejo: at a guesthouse counter, a traveller shows his ID in hand while the innkeeper checks it against her ledger; in the corner, an old photocopier sits switched off

Every summer the same scene repeats across Spain: receptions asking for a photocopy of the DNI, holiday flats demanding a photo of the passport by WhatsApp before handing over keys, check-in forms requesting the document scanned on both sides. And every summer brings more complaints. Spain’s consumer watchdog FACUA repeated the reminder on 7 July, and urged travellers to report to the data protection authority any lodging that demands one1.

The confusion has an honest origin: Royal Decree 933/2021 obliges every Spanish lodging to register and report each traveller’s data, and a photocopy looks like the fastest way to avoid typos. The people who get caught out are usually the smallest operators, filing in good faith for the Interior Ministry and finding out late that their folder of copies exposes them from the other side.

What Royal Decree 933/2021 requires (and what it doesn’t)

The decree demands three things of your rental:

  1. Collect each traveller’s data listed in its Annex I: name and surnames, sex, document number and type, support number, nationality, date of birth, habitual residence, phone numbers, email, number of travellers and the family relationship if any of them is a minor; plus the contract, check-in and check-out, property and payment details2.
  2. Keep a digital register of that data (article 5.1) for three years from the end of the contracted service (article 5.3)3.
  3. Report it to SES.HOSPEDAJES immediately and, at the latest, within 24 hours of the contracted services starting (article 6.3)4.

About the document itself the decree says one thing only, and it is not that you keep it:

“The entry reports and sheets shall be provided by the lodging or vehicle rental establishment, which shall be responsible for the accuracy of the data recorded in them, so that they match the documents or systems evidencing the identity of the persons, which the users of these services must exhibit or provide.”

Royal Decree 933/2021, article 4.35

Exhibited: the traveller shows it to you, and you answer for what you wrote matching what you saw. The Interior Ministry repeats it in those same terms in its official FAQ, where the word copy does not appear once across the thirty answers6.

That difference decides whether your check-in complies or exposes you. You transcribe the data and keep it for three years because the decree tells you to. Nobody asks you for an image of the document, so if you choose to keep one, you answer for it and for whatever happens to it.

What the AEPD says, verbatim

The AEPD published a dedicated note on lodgings on 17 June 2025, answering exactly this question. Its conclusion:

“Requesting a copy of the National Identity Document or Passport violates the principle of data minimisation established in article 5.1.c) of the GDPR and constitutes excessive data processing.”

AEPD, note on the hospedajes register (17 June 2025)7

That article 5.1.c) requires the data you process to be adequate, relevant and limited to what is necessary for the purpose you collected it for. The agency reads it strictly in its decisions: the provision does not cap excess, it caps necessity, so if the objective can be reached without that processing, that is how it must be reached8. The note gives three reasons why a copy fails the test:

  • It carries data the rule never asks for. A full ID card includes the photograph, the expiry date, the card access number and the parents’ names, and none of them is in Annex I.
  • It creates a risk you did not have. A folder of document copies is an identity-theft risk that, in the note’s words, “must be avoided or, at the least, effectively mitigated”.
  • It authenticates nothing. An image arriving over WhatsApp does not prove that the sender is the document holder.

And it saves you no form. The document does not carry the traveller’s phone numbers or email, nor how many people are staying, nor the family relationship when a minor is involved, nor a single transaction field: contract reference and date, check-in and check-out times, payment method type and holder. You have to ask for all of that anyway.

AEPD fines for copying guests’ ID: 30,000 and 25,000 euros

This is not theory. Two AEPD decisions put numbers on it. The first imposed 30,000 euros on a Balearic hotel for what it did with the passport it ran through the scanner at check-in (resolution PS/00078/2021)9. The complaint came from a Dutch guest whose document was scanned despite his express objection.

What was sanctioned is finer than a photocopy. The agency did not find it proven that the hotel kept a full image of the passport: the scan turned the characters into text by OCR. What had no legal basis was the photograph pulled out of it, which travelled to the bar and dining-room devices so staff could recognise the guest charging consumption to the room. The rest of the data was covered by the legal registration duty. The photograph was not, and that is why the infringement was of article 6 of the GDPR.

So it takes less than you think. You do not have to keep an image of the document to be fined: reusing one field taken from it for something the guest register does not ask of you is enough.

The second, resolution PS/00499/2022, fined the manager of an Airbnb-listed flat in Barcelona 25,000 euros for requiring images of both sides of the DNI from all seven guests before handing over the keys8. His defence was that he asked for them to comply with the Mossos d’Esquadra guest register. It did not help:

“[The respondent] has infringed article 5.1.c) of the GDPR, having required the image of both sides of the D.N.I. in order for them to obtain the keys to the accommodation they had booked, since such data are not necessary for the processing carried out by the respondent.”

AEPD, resolution PS/00499/2022, legal ground II8

It is the precedent to keep at hand when someone invokes the police duty: a police register being demanded of you does not entitle you to demand an image of the document.

That fine could also have been twice as large. The opening decision proposed 50,000 euros because the complainant also alleged that a selfie was demanded from every guest; with that point unproven, the resolution came down to 25,0008.

The file, however, did not stop at 25,000. The total came to 75,000, because the AEPD added a second infringement of 50,000 euros under article 13 of the GDPR: the information the manager gave guests about the processing was incomplete8. His privacy notice was missing, among other things:

  • the identity and contact details of the controller;
  • the legal basis for the processing;
  • the recipients of the data;
  • the retention period, or the criteria for setting it;
  • the right to lodge a complaint with a supervisory authority;
  • whether providing the data is a legal or contractual requirement, and what happens if it is not provided.

Copying the document exposes you. A badly written privacy notice can cost you twice as much.

And the risk comes from both sides. For not filing the guest report, Spain’s Interior Ministry fines you: late or erroneous filing is a minor infringement, between 100 and 600 euros, and failing to report guest data at all is a serious one, between 601 and 30,0006. For collecting too much, the AEPD fines you. Compliance sits exactly in the middle: every Annex I field, and not one more.

How to run check-in without copying the guest’s ID

The AEPD’s own note describes the valid routes, and the first is the simplest:

“The AEPD considers that it could be sufficient for individuals to provide or complete a form collecting exclusively the data required in sections A.3 and B.3 of Annex I of the Royal Decree […]. This form may be completed online or in person at the lodging.”

AEPD, note on the hospedajes register (17 June 2025)7

In person. The guest fills in (or confirms with you) that form with the Annex I data, and you visually check that it matches the document they show you. Look, compare, hand it back. The AEPD puts it this way: “it could be enough to visually check the correspondence between the data provided and the identity document exhibited”.

Remotely (online check-in). With nobody in front of you, the note accepts three mechanisms for authenticating what the traveller has declared:

  • a digital certificate belonging to the traveller;
  • a check against the payment method details, which have to match what was declared;
  • a security code sent to the guest’s phone or email, fields Annex I already obliges you to collect anyway.

For the guest carrying no smartphone and holding no email address, the code still works: it arrives by SMS on any handset, and the Ministry itself settles that Annex I contact field in one line, because if the traveller has no email address, providing a mobile number is enough6. With neither a mobile nor an email, what is left is the other two routes, the digital certificate or the check against the payment method details, and if none of them fits, a visual check at the moment you hand over the keys.

The agency does not rule out other procedures, but it leaves the burden where it was: the one who has to assess whether they are compatible with the GDPR is the controller, meaning you. What that role involves, towards the Ministry and towards your check-in provider, is set out in GDPR duties when registering guests. What is not on the list: “send me a photo of your passport on WhatsApp”.

With minors. No copy question even arises, because a child under fourteen neither signs the report nor supplies their own data: “their data shall be provided by the adult of legal age they are accompanied by”, says article 4.2 of the decree5. If that adult is not a parent, you must record the capacity that entitles them, such as guardian, teacher or sports coach6. Ages, signatures and edge cases are covered in our guide to minors in Spanish guest registration.

What if the guest consents? A consent conditioned on receiving the keys is hardly free: article 7.4 of the GDPR requires you to look at precisely that, whether the performance of a service is made conditional on accepting processing that is not necessary to perform the contract10. And even if it were free, it would not fix the underlying objection, which is about necessity rather than permission: with their yes you would still be collecting data you do not need.

Quick reference: which check-in practices comply and which don’t

The AEPD note and the two resolutions put the most common front-desk practices on one side of the line or the other7.

PracticeCompliant?
Looking at the ID and checking the form data against itYes
Online check-in form with the Annex I fieldsYes
Verification by SMS/email code or payment dataYes
Photocopying or scanning the ID “for the records”No
Requesting an ID photo by WhatsApp or email before arrivalNo
Demanding a selfie with the documentNo

RegistroViajero’s digital check-in is built on this exact logic: each guest fills in their own data in their own language (9 available), the system validates the Annex I fields, and the report goes to SES.HOSPEDAJES on time. No document photos, no photocopy archive to guard, no manual typing into the portal. You can see how it works if you want your Spanish rental running this way this summer.

Frequently asked questions

Can I ask a guest in Spain to show me their ID? Asking a guest to show you their ID is allowed, and in fact required: article 4.3 of Royal Decree 933/2021 makes you responsible for the report’s data matching the document, which the traveller is obliged to exhibit. What you cannot do is keep a copy, photo or scan.

What if the guest sends me an ID photo on their own initiative? If a guest sends you an ID photo on their own initiative, don’t keep it. The legal problem is not who initiates the sending but the processing: storing document copies is excessive processing per the AEPD.

How do I meet the three-year record duty then? You meet the three-year record duty by keeping the data, not the documents. Article 5 of Royal Decree 933/2021 requires a digital register with the Annex data for three years after each stay.

What can happen if I keep photocopying? What can happen if you keep photocopying is a complaint to the AEPD and a GDPR fine. The closest precedent is the 25,000 euros imposed on a flat manager who required images of both sides of the DNI before handing over the keys (PS/00499/2022), a file whose total reached 75,000 because a separate infringement was added, the article 13 duty to inform the guest. In another case a hotel paid 30,000 euros for reusing the photograph pulled from a scanned passport (PS/00078/2021).

Does this change the data I send to SES.HOSPEDAJES? No, this does not change the data you send to SES.HOSPEDAJES: the Annex I fields and the 24-hour deadline stay the same. What changes is how you collect, not what you report.


This article is informational and is not legal advice.

Sources

  1. FACUA reminds hotels and tourist accommodation that they may not demand a photo or scan of the DNI at check-in, 7 July 2026 (FACUA-Consumidores en Acción). ↩

  2. Real Decreto 933/2021, Annex I, section A), items 3 and 4, consolidated text (BOE). ↩

  3. Real Decreto 933/2021, article 5, paragraphs 1 and 3, consolidated text (BOE). ↩

  4. Real Decreto 933/2021, article 6.3, consolidated text (BOE). ↩

  5. Real Decreto 933/2021, article 4, paragraphs 2 and 3, consolidated text (BOE, in Spanish). ↩ ↩2

  6. Preguntas frecuentes de hospedajes y alquiler de vehículos dirigidas a usuarios, updated 09/04/2025, questions 21, 24, 25 and 29 (Spanish Ministry of the Interior, PDF). ↩ ↩2 ↩3 ↩4

  7. AEPD note on copies of identity documents in lodgings, 17 June 2025, PDF (AEPD). ↩ ↩2 ↩3

  8. AEPD resolution PS/00499/2022, PDF (AEPD). ↩ ↩2 ↩3 ↩4 ↩5

  9. AEPD resolution PS/00078/2021, PDF (AEPD). ↩

  10. Regulation (EU) 2016/679, article 7(4), English version (EUR-Lex). ↩

More related guides and news on tourist accommodation

Let's talk

Got questions, or want a demo of RegistroViajero? Pick how you would like to reach us.

Or write to us here

Message sent

Thanks for reaching out. We'll get back to you as soon as possible.

We'll do our best to get back to you as soon as possible. Spanish business-hours restrictions apply.